Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-38545

76
FAUCET Score

CVE-2023-38545 is a critical heap-based buffer overflow vulnerability in curl's SOCKS5 proxy handshake, affecting products from Fedora, Haxx, Microsoft, and NetApp. It occurs when curl attempts to pass a hostname longer than 255 bytes to the proxy, leading to an incorrect local variable state and the oversized hostname being copied to a heap buffer. With a CVSS score of 9.8, this vulnerability has a network attack vector, low attack complexity, and can lead to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating high awareness.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.69.0, < 8.4.0CPE matchmatch criteria
cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:*
37CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
78.48%
Probability of exploitation in next 30 days
EPSS Percentile
99.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.7848 is in the 98th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (48)

gcppatch availablevia llm_extracted
View patch
hikvisionpatch availablevia llm_extracted
latchsetpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 23H2 for x64-based SystemsFixed in: 10.0.22631.2715
View patch
microsoftpatch availablevia msrc
Product: Microsoft Office LTSC 2021 for 64-bit editionsFixed in: https://aka.ms/OfficeSecurityReleases
microsoftpatch availablevia msrc
Product: Microsoft Office LTSC 2021 for 32-bit editionsFixed in: https://aka.ms/OfficeSecurityReleases
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for 32-bit SystemsFixed in: 10.0.17763.5122
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for x64-based SystemsFixed in: 10.0.17763.5122
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for ARM64-based SystemsFixed in: 10.0.17763.5122
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019Fixed in: 10.0.17763.5122
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019 (Server Core installation)Fixed in: 10.0.17763.5122
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022Fixed in: 10.0.20348.2113
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022 (Server Core installation)Fixed in: 10.0.20348.2113
View patch
microsoftpatch availablevia msrc
Product: Windows 11 version 21H2 for x64-based SystemsFixed in: 10.0.22000.2600
View patch
microsoftpatch availablevia msrc
Product: Windows 11 version 21H2 for ARM64-based SystemsFixed in: 10.0.22000.2600
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 21H2 for 32-bit SystemsFixed in: 10.0.22000.2600
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 21H2 for ARM64-based SystemsFixed in: 10.0.19044.3693
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 21H2 for x64-based SystemsFixed in: 10.0.19044.3693
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 22H2 for ARM64-based SystemsFixed in: 10.0.22621.2715
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 22H2 for x64-based SystemsFixed in: 10.0.22621.2715
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 22H2 for x64-based SystemsFixed in: 10.0.19045.3693
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 22H2 for ARM64-based SystemsFixed in: 10.0.19045.3693
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 22H2 for 32-bit SystemsFixed in: 10.0.19045.3693
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 23H2 for ARM64-based SystemsFixed in: 10.0.22631.2715
View patch
microsoftpatch availablevia msrc
Product: Microsoft Office 2019 for 32-bit editionsFixed in: https://aka.ms/OfficeSecurityReleases
microsoftpatch availablevia msrc
Product: Microsoft Office 2019 for 64-bit editionsFixed in: https://aka.ms/OfficeSecurityReleases
microsoftpatch availablevia msrc
Product: Microsoft 365 Apps for Enterprise for 32-bit SystemsFixed in: https://aka.ms/OfficeSecurityReleases
microsoftpatch availablevia msrc
Product: Microsoft 365 Apps for Enterprise for 64-bit SystemsFixed in: https://aka.ms/OfficeSecurityReleases
nodejspatch availablevia llm_extracted
Fixed in: 5.4.3
redhatpatch availablevia redhat_api
Product: Red Hat Satellite 6.14 for RHEL 8Fixed in: puppet-agent-0:7.27.0-1.el8sat
View patch
redhatpatch availablevia redhat_api
Product: Satellite Client 6 for RHEL 6Fixed in: puppet-agent-0:7.27.0-1.el6sat
View patch
redhatpatch availablevia redhat_api
Product: Satellite Client 6 for RHEL 7Fixed in: puppet-agent-0:7.27.0-1.el7sat
View patch
redhatpatch availablevia redhat_api
Product: Satellite Client 6 for RHEL 8Fixed in: puppet-agent-0:7.27.0-1.el8sat
View patch
redhatpatch availablevia redhat_api
Product: Satellite Client 6 for RHEL 9Fixed in: puppet-agent-0:7.27.0-1.el9sat
View patch
redhatpatch availablevia redhat_api
Product: Text-Only JBCSFixed in: jbcs-httpd24-curl
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-curl-0:8.4.0-2.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: curl-0:7.76.1-26.el9_3.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: curl-0:7.76.1-23.el9_2.4
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-curl-0:8.4.0-2.el7jbcs
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: curl-0:7.76.1-14.el9_0.9
View patch
barracudavendor investigatingvia llm_extracted
boschvendor investigatingvia llm_extracted
clamavvendor investigatingvia llm_extracted
consulvendor investigatingvia llm_extracted
freshrssvendor investigatingvia llm_extracted
qdrantvendor investigatingvia llm_extracted
symantecvendor investigatingvia llm_extracted
verbbvendor investigatingvia llm_extracted

Vendor Advisories (14)

gcpllm-gcp-e028ccdedcbc6cccCRITICAL

HP Device Manager Vulnerability Update (5.0.16)

Mar 9, 2026
nodejsllm-nodejs-91bc25f14cc604adCRITICAL

Third-Party Package Updates in Splunk User Behavior Analytics (UBA) - July 2025

Jul 30, 2025
qdrantllm-qdrant-f0b63a71013e0196

Heap Based Buffer Overflow Vulnerability in cURL

Nov 7, 2023
symantecllm-symantec-3655481971cd8700

Heap Based Buffer Overflow Vulnerability in cURL

Nov 7, 2023
verbbllm-verbb-c0a88f9c7526bbbc

Heap Based Buffer Overflow Vulnerability in cURL

Nov 7, 2023
consulllm-consul-162b8e993a88936a

Heap Based Buffer Overflow Vulnerability in cURL

Nov 7, 2023
barracudallm-barracuda-af885b6a87901344

Heap Based Buffer Overflow Vulnerability in cURL

Nov 7, 2023
clamavllm-clamav-e459d21f522f9726

Heap Based Buffer Overflow Vulnerability in cURL

Nov 7, 2023
boschllm-bosch-be7f379f1622b313

Heap Based Buffer Overflow Vulnerability in cURL

Nov 7, 2023
freshrssllm-freshrss-677ced354f6bb128

Heap Based Buffer Overflow Vulnerability in cURL

Nov 7, 2023
redhatCVE-2023-38545Important

curl: heap based buffer overflow in the SOCKS5 proxy handshake

Oct 11, 2023
latchsetllm-latchset-debc2cbbd1f2d4f0HIGH

Hotfix for curl and libcurl vulnerability

Oct 11, 2023
hikvisionllm-hikvision-f8712fe746d238ceHIGH

SOCKS5 heap buffer overflow

Oct 11, 2023
microsoft2023-Oct/CVE-2023-38545Important

Hackerone: CVE-2023-38545 SOCKS5 heap buffer overflow

Oct 10, 2023

References

cert-portal.siemens.com / productcert/html/ssa-082556.html
cert-portal.siemens.com / productcert/html/ssa-093430.html
cert-portal.siemens.com / productcert/html/ssa-507364.html
cert-portal.siemens.com / productcert/html/ssa-832273.html
cert-portal.siemens.com / productcert/html/ssa-943925.html
github.com / bcdannyboy/CVE-2023-38545
github.com / dbrugman/CVE-2023-38545-POC
github.com / UTsweetyfish/CVE-2023-38545
curl.se / docs/CVE-2023-38545.html
PatchThird Party Advisory
seclists.org / fulldisclosure/2024/Jan/34
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2024/Jan/37
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2024/Jan/38
Mailing ListThird Party Advisory
forum.vmssoftware.com / viewtopic.php
lists.fedoraproject.org / archives/list/[email protected]/message/OGMXNRNSJ4ETDK6FRNU3J7SABXPWCHSQ
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20231027-0009
Third Party Advisory
security.netapp.com / advisory/ntap-20240201-0005
Third Party Advisory
support.apple.com / kb/HT214036
Third Party Advisory
support.apple.com / kb/HT214057
Third Party Advisory
support.apple.com / kb/HT214058
Third Party Advisory
support.apple.com / kb/HT214063
Third Party Advisory
secpod.com / blog/high-severity-heap-buffer-overflow-vulnerability
PatchThird Party Advisory